TGIF! And we are sure you have plans for the weekend; so, it turns out, does the EU, just on a slower clock.
Europe spent months fighting over how to police medical AI, signed the result last month, then set the alarm for August 2028, which is either plenty of time or no time at all, depending on how your compliance team sleeps.
That gap is today's whole story: two years to work out where a line falls before the rules actually bite. With that in mind, let's take the long way through it.
One Model, Two Rooms
An AI model that reads cancer images in a university lab, for research purposes and never on a patient, falls outside the scope of the AI Act. Install the same model in a hospital, run it on real people, and, in most cases, it becomes a high-risk medical device that must comply with the Act in full. In that example, what flips the classification is where the system is used, not the system itself.
That is the fault line the EU wrote into its AI Act when it signed July's amendments into law, fixing August 2, 2028, as the day the rules for high-risk systems, medical AI among them, come into force. The Act carves out two shelters for research: one for testing and development before a system reaches the market, and a scientific-use exemption for AI "specifically developed and put into service for the sole purpose of scientific research and development."